A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/neuvector/neuvector(Go) | 0 | 0.0.0-20231003121714-be746957ee7c | N/A |
CVSS Metrics